Threatlocker

Prev Next

This is a Discovery Integration.

  • This integration collects 90 days of history by default upon first connection.


Collect Required Information from Vendor

IMPORTANT!

You must meet the following prerequisite(s) before you can continue.

  1. Log in to the Threatlocker Portal.

  2. Go to the Administrators page and select the API Users tab.

  3. Select the New API User button, name it Calero and select the Generate API Token.

  4. Copy/save the following field(s) for use when onboarding this Integration:

    • API Key (i.e., the token)

      IMPORTANT!

      You MUST copy/save this token for use when onboarding this Integration (see below). It will not be visible again.

  5. Set the API Expiration date to 365 days.

  6. Give the token the following roles:

    • View organization

    • View computers

    • View reports

    • View system audit

    • View ThreatLocker threats

    • View ThreatLocker policies

    • View ThreatLocker remediations

    • View unified audit

  7. Give the token “All” organizations.

  8. Select the Create button.

Onboard This Discovery Integration

  1. Go to SaaS Management > Applications.

  2. Select Add Integration.

  3. Select the Discovery Apps tab, then select the card with the vendor's name.

  4. From the API tab, enter the field(s) you copy/saved above.

  5. Select the Authorize button.

SUCCESS!

You will now be redirected to the Integrations page in Calero.com, where the data sync will continue in the background, and you can monitor progress.


SUGGESTION:

Access Help through your Calero.com instance if links between articles return errors or if there are fewer sections in the Help menu than expected. Doing so will ensure you see all Help articles.